Smoozen privacy overview

Data boundaries are explicit.

This Preview overview explains the intended product boundary. It is not a final privacy notice, data-processing agreement, or legal advice.

Preview privacy boundaryPurpose-limited and client-authority led

Privacy by boundary

Only the approved context should cross the line.

Privacy is expressed as a set of visible decisions about purpose, scope, authority, retention, and evidence.

01

Client authority

The client remains the system of record for identity, consent, bookings, payments, safety, and final user-facing records.

02

Minimisation

Smoozen should receive only approved fields required for the enabled capability. Passwords, payment details, identity documents, private messages, safety notes, and unrestricted records are excluded by default.

03

Advisory processing

Recommendations may be incomplete or wrong. Human review and deterministic client controls are required before publication or consequential action.

04

Tenant separation

A client context is established by authenticated deterministic controls. Cross-client visibility is not a default product feature.

05

Retention and deletion

Retention, export, deletion, model-provider use, and network removal must be specified in the approved client launch profile and data schedule.

06

Evidence and provenance

Public or operational metrics need a source, threshold, anonymisation review, and named approval before they are presented as evidence.

Before real-data launch

Make the privacy decisions reviewable.

Each client profile should name an owner and leave an evidence trail before production enablement.

Approval required

Data schedule

Name the fields, purpose, source, retention period, and approved recipients for each enabled capability.

Approval required

Consent and notice

Confirm the client-owned notice, consent flow, human-review path, and escalation owner before real data is enabled.

Approval required

Deletion and incidents

Document deletion requests, exports, connector removal, incident contacts, and rollback or containment steps.

Client system of record

Smoozen assists within the approved boundary.

It does not silently become the owner of a person's identity, consent, booking, payment, safety record, or final communication.

View security controls
Before real-data launch: Counsel and named privacy owners must approve the applicable notice, data schedule, consent flow, retention, deletion, and incident process.

Security and trust Terms placeholder